AIR
AIR builds a runtime context firewall that vets and monitors the skills, plugins, and MCP tools enterprise AI agents connect to.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
AIR (air.security) is a Tel Aviv-based startup founded in February 2026 by Yair Saban (CEO) and Niv Hoffman (CTO), both veterans of Israel’s Unit 8200 signals-intelligence unit. The company emerged from stealth on September 1, 2026 with $50 million raised across two seed rounds ($10M led by Sequoia Capital, followed by $40M led by Greenoaks), with participation from individual investors including Wiz co-founder Yinon Costica. Former Disney and Costco CISO Ryan Knisley joined as Chief Strategy Officer. At the time of its funding announcement the company reported roughly 40 employees and more than 20 paying customers, about a quarter of them large enterprises, concentrated in financial services and pharma.
The product, marketed as a ‘context firewall for AI agents,’ sits between enterprise AI agents and the external skills, plugins, and Model Context Protocol (MCP) servers those agents try to use. It has four components: Control (discovery and policy governance of agent fleets), Filter (pre-deployment vetting of add-ons for malicious instructions, excessive permissions, or supply-chain risk), Defend (runtime monitoring and blocking), and a curated Marketplace of pre-vetted add-ons. AIR’s own research, cited in press coverage, claims to have found over 17,800 public AI add-ons with 6.7 million installs relying on untrusted instruction sources, plus fake ‘skills’ impersonating Anthropic and OpenAI to slip past review.
The company’s differentiator is narrow focus: rather than general LLM security or prompt-injection filtering, it specifically targets the software-supply-chain risk created by autonomous agents installing third-party skills and MCP tools without human review. This is a genuine and fast-growing problem as agentic AI adoption accelerates, but AIR competes with several other very recently funded ‘AI agent security’ and ‘MCP security’ entrants, and as a six-month-old company it has no long-run track record.
Innovation Matrix Assessment
Shipped four distinct product modules and published original threat research within six months of founding, but it is too early to show a repeatable cadence of advances.
Addresses a concrete, growing operational gap — enterprises deploying AI agents with little visibility into what plugins or MCP tools those agents install and use.
$50M raised from top-tier investors (Sequoia, Greenoaks) and 20+ named customers within six months is unusually strong momentum for a company this young, per independent TechCrunch, SecurityWeek, and Calcalist reporting.
AI agent and MCP security is a real emerging category, but AIR is one of several well-funded entrants racing into it simultaneously, not a clear category creator.
No independent third-party testing, named customer incident, or analyst validation was found; the threat-research statistics cited in press coverage originate from AIR itself.
Agentic AI supply-chain risk is likely to remain a live problem for years, but the vendor landscape is crowded and could consolidate quickly.
Why CISOs Should Care
As agents begin auto-installing third-party skills and MCP integrations, CISOs need a control point to vet and monitor those add-ons before they touch internal systems or data.
What Makes It Different
Rather than filtering LLM prompts or outputs generally, AIR focuses specifically on vetting and governing the software supply chain of agent add-ons (skills, plugins, MCP servers) before and during runtime.
The Matrix Verdict
57/100 — INCREMENTAL INNOVATOR
AIR shows genuine product breadth and unusually strong early funding and customer traction for a six-month-old company, but has no independently verified efficacy evidence yet and competes in a fast-forming, crowded niche.
Editorial Note: Claims vs. Verified Findings
Funding amount, investors, founder backgrounds, and customer count are corroborated by independent outlets (TechCrunch, SecurityWeek, Calcalist). The specific threat-research statistics (17,800 add-ons, 6.7M installs) are AIR's own self-published research and have not been independently replicated.
Sources
- TechCrunch — https://techcrunch.com/2026/09/01/air-raises-50m-to-help-companies-vet-the-skills-and-add-ons-ai-agents-use/
- SecurityWeek — https://www.securityweek.com/ai-agent-firewall-startup-air-security-emerges-from-stealth-with-50-million/
- Calcalist/Ctech — https://www.calcalistech.com/ctechnews/article/r13apdnugg
- Official site — https://www.air.security/
Alternatives to AIR
Adaptive Security
AI-driven platform that simulates deepfake, voice, and multichannel social-engineering attacks to train and test organizations against next-generation phishing.
Quilr
Early-stage agentic AI security startup building a 'Service-as-Software' platform to guard against human-related breaches and secure AI agent…
Tenzai
An agentic AI penetration testing startup building autonomous 'AI hackers' to find and validate exploitable vulnerabilities at a…
Zenity
Governance and security platform for AI agents and low-code/no-code development, securing agent identity, permissions and behavior across the…
Alice (formerly ActiveFence)
Israeli AI security company (rebranded from ActiveFence in January 2026) offering a lifecycle platform to test, guard, and…
Reco
Reco secures the "agentic ecosystem" — mapping what AI agents can access across SaaS and enterprise apps, detecting…